Deployment Sovereignty
The Vault is designed to give organisations full control over where and how their custody infrastructure runs. Choose from three deployment models depending on your data residency requirements, operational capacity, and regulatory obligations.
Deployment Models at a Glance
| SaaS | Hybrid | On-Premises | |
|---|---|---|---|
| Infrastructure | Managed by The Vault | Shared | Fully customer-managed |
| Key share custody | Server shares in The Vault cloud | Server shares split across both environments | All shares on customer infrastructure |
| Data residency | The Vault cloud region | Split — sensitive data on-prem | Fully within customer perimeter |
| Operational burden | Minimal | Moderate | Full |
| Time to go live | Days | 1–2 weeks | 2–4 weeks |
| Best for | Startups, fintechs | Regulated entities wanting managed services + key control | Banks, institutions with strict data residency |
SaaS (Cloud-Hosted)
The fully managed option. All platform services, server signers, and data are hosted in The Vault’s cloud infrastructure.
You manage:
- API integration from your application
- Mobile signer devices (your team holds them)
- Transaction policies and approval workflows
We manage:
- Infrastructure, uptime, scaling, and monitoring
- Database backups and disaster recovery
- Server signer availability and key share encryption
- Software upgrades and security patches
Even in SaaS mode, the MPC threshold model ensures The Vault cloud alone cannot move funds. Your mobile signer(s) must participate in every signing session.
Hybrid
The balanced option. Platform services run in The Vault cloud, but one or more MPC key shares remain on your own infrastructure.
You manage:
- On-premises server signer(s) — hosting, uptime, monitoring
- Mobile signer devices
- Your key share backup and recovery procedures
We manage:
- All cloud-hosted platform services (API gateway, signing coordinator, wallet operations, policy engine, identity, dashboard)
- Cloud-side server signer
- Software upgrades for the platform layer
Why hybrid?
The hybrid model lets regulated organisations satisfy key custody requirements without running the full platform stack. By holding a server signer on-premises, you ensure that no signing operation can complete without infrastructure you control — while still benefiting from managed platform services.
On-Premises (Self-Hosted)
The full sovereignty option. Every component — services, signers, database, and key material — runs within your own network perimeter.
You manage:
- Compute platform provisioning and maintenance
- All Vault services (deployed from the platform’s deployment package)
- Database hosting, backups, and disaster recovery
- KMS configuration and key management
- Network security, TLS certificates, and access controls
- Software upgrades (new releases provided by The Vault)
We provide:
- The deployment package, installation runbook, and operator CLI
- Technical onboarding and upgrade guidance
- Security advisories and patch releases
On-premises deployment supports the same API surface and feature set as the cloud deployment. The only difference is infrastructure ownership and operational responsibility.
Key Sovereignty
Across all deployment models, The Vault’s configurable k-of-n MPC threshold (default 3-of-4) ensures that no single party can unilaterally move funds.
| Deployment | Who holds key shares | Can The Vault move funds alone? |
|---|---|---|
| SaaS | 2 server shares (The Vault cloud) + 2 mobile shares (your devices) | No — requires at least 1 mobile signer |
| Hybrid | 1 server share (cloud) + 1 server share (your infra) + 2 mobile shares (your devices) | No — requires your signer + mobile |
| On-Premises | 2 server shares (your infra) + 2 mobile shares (your devices) | N/A — The Vault has no access |
In every model, at least one key share that you physically control must participate in every signing ceremony. This is a cryptographic guarantee, not a policy setting — it cannot be bypassed.
Data Residency
With on-premises or hybrid deployment, you control where sensitive data lives:
| Data Type | SaaS | Hybrid | On-Premises |
|---|---|---|---|
| Encrypted key shares | The Vault cloud | Split | Your infrastructure |
| Transaction records | The Vault cloud | The Vault cloud | Your infrastructure |
| Audit logs | The Vault cloud | The Vault cloud | Your infrastructure |
| User identity data | The Vault cloud | The Vault cloud | Your infrastructure |
| KMS root key | The Vault-managed KMS | Your KMS | Your KMS |
If your organisation is subject to data residency regulations (e.g., GDPR, MAS TRM, local banking rules), consider on-premises or hybrid deployment to ensure all regulated data remains within your jurisdictional boundary.
Choosing a Model
I want to move fast
SaaS is the right choice. You get a production-ready custody platform in days, with no infrastructure to manage. You still hold mobile signer devices, so funds cannot move without your explicit participation.
Next Steps
- On-Premises Installation — deployment overview, prerequisites, and what’s in the onboarding package
- Key Backup — backup procedures for each deployment model
- Operations — monitoring, backup, disaster recovery, and upgrades